🛠 Visa Introduces VVAH for Automated Code Protection

The company has released an open-source tool called VVAH (Visa Vulnerability Agentic Harness) — an agentic pipeline for automated vulnerability discovery, remediation, and validation using AI. The system utilizes multi-agent voting to minimize false positives and supports Claude, OpenAI, and local LLMs.

🌍 The transition to Agentic SAST allows for a radical reduction in MTTA (Mean Time to Action/Remediation) — the time from vulnerability detection to the implementation of a fix — turning AppSec into a self-healing code cycle.

👤 This serves as an example of AI transitioning from merely writing code to performing critical engineering tasks for security assurance.

Source 1: https://github.com/visa/visa-vulnerability-agentic-harness Source 2: https://corporate.visa.com/content/dam/VCOM/corporate/visa-perspectives/security-and-trust/documents/project-glasswing.pdf